CVE-2026-92879: Resource Consumption in vgmstream
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as ae37662ad626254ddd96ad69ac263792d7a92024. Applying a patch is advised to resolve this issue.
AI Analysis
Technical Summary
This vulnerability in vgmstream (up to r2117) involves the parse_mus function in src/meta/mus_acm.c, where specially crafted input can lead to excessive resource consumption. The issue can be triggered remotely without privileges or user interface requirements, but user interaction is needed. The vulnerability has a CVSS 4.0 base score of 5.3 (medium severity). A patch has been identified (commit ae37662ad626254ddd96ad69ac263792d7a92024) to address this issue.
Potential Impact
Successful exploitation of this vulnerability can cause resource consumption on the affected system, potentially leading to denial of service or degraded performance. There is no indication of code execution, data disclosure, or privilege escalation. The attack can be launched remotely but requires user interaction.
Mitigation Recommendations
Apply the official patch identified by commit ae37662ad626254ddd96ad69ac263792d7a92024 to resolve this vulnerability. No other mitigation guidance is provided. Since the patch is available, updating to the fixed version is the recommended action.
CVE-2026-92879: Resource Consumption in vgmstream
Description
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as ae37662ad626254ddd96ad69ac263792d7a92024. Applying a patch is advised to resolve this issue.
CVSS v4.0
Score 5.3medium
Affected software
vgmstream
pkg:github/vgmstream/vgmstreamcpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in vgmstream (up to r2117) involves the parse_mus function in src/meta/mus_acm.c, where specially crafted input can lead to excessive resource consumption. The issue can be triggered remotely without privileges or user interface requirements, but user interaction is needed. The vulnerability has a CVSS 4.0 base score of 5.3 (medium severity). A patch has been identified (commit ae37662ad626254ddd96ad69ac263792d7a92024) to address this issue.
Potential Impact
Successful exploitation of this vulnerability can cause resource consumption on the affected system, potentially leading to denial of service or degraded performance. There is no indication of code execution, data disclosure, or privilege escalation. The attack can be launched remotely but requires user interaction.
Mitigation Recommendations
Apply the official patch identified by commit ae37662ad626254ddd96ad69ac263792d7a92024 to resolve this vulnerability. No other mitigation guidance is provided. Since the patch is available, updating to the fixed version is the recommended action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-17T08:17:32.479Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aabf68d55bf5e2cf57b3480
Added to database: 09/17/2026, 14:17:49 UTC
Last enriched: 09/17/2026, 14:31:29 UTC
Last updated: 09/17/2026, 23:06:22 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.